Skip to content

Security1 publisher2 min readPublished

EU auditors find the cooperation between national CSIRTs and EU-CyCLONe still undefined

The European Court of Auditors examined the years 2022 to 2025 and reported that the EU's two cyber networks have yet to define how they work together, and that the European Cybersecurity Alert System was not operational.

The Watch · Security desk

Illustration accompanying EU auditors find the cooperation between national CSIRTs and EU-CyCLONe still undefined

What happened

  • The European Court of Auditors reported that the EU has built a cybersecurity cooperation framework, but that several measures needed for an effective response to significant and large-scale incidents are still incomplete.
  • Cooperation between the CSIRTs network of national incident teams and EU-CyCLONe, which supports cooperation during EU-level crises, has not yet been formally defined.
  • Two hubs of the European Cybersecurity Alert System that the auditors examined, ATHENA and ENSOC, had not started operating because of procurement delays.
  • Recipients of EU cybersecurity grants assess the ownership and control of third parties they fund, and the European Cybersecurity Competence Centre does not verify those assessments.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure An incident that spans several member states and exceeds one country's capacity is exactly the case the EU layer exists for, and the route from the national teams to the EU crisis body has no agreed form yet.
  • constraint Reporting under NIS 2 is not redistribution. National security law limits what a receiving authority can pass on, so a playbook that treats one notification as reaching every peer CSIRT is wrong about what happens next.
  • cost Member states are funding an average of EUR 200 million a year through the Digital Europe Programme while the hubs meant to carry alerts remain in procurement.
  • exposure Grant recipients carry the entire third-party ownership check themselves, and the control meant to keep sensitive security information away from non-EU authorities rests on their own assessment.

The CSIRTs network brings together the national teams that handle incidents. EU-CyCLONe supports cooperation once a crisis is being managed at EU level [5]. The Cyber Blueprint, adopted in 2025, largely clarifies roles and responsibilities for managing major cybersecurity crises, according to the auditors [3].

Even where a route exists, national security law limits what a receiving authority can pass on. National security laws differ, and the updated EU rules, including the NIS 2 Directive, are still being implemented; the auditors said both factors can make it harder for the EU networks to identify threats early and coordinate an effective response [6].

George-Marius Hyzler, the ECA member responsible for the audit, said: "The EU has made progress in building a cybersecurity cooperation framework, but it is not yet working as effectively as it should" [7]. He also said: "When a serious cyber incident occurs, timely and actionable information is essential. Without it, networks and mechanisms lose much of their added value" [8].

The European Cybersecurity Alert System was not operational at the time of the assessment [9]. It also lacked cooperation agreements, a common classification system and technical standards [11]. Under the 2021-2027 EU budget, EUR 1.4 billion has been allocated to cybersecurity through the Digital Europe Programme, the EU's main source of cybersecurity funding [12]. Across the seven years of that budget, the allocation averages EUR 200 million a year [13].

The audit covered 2022 to 2025 and asked whether EU actions effectively supported the detection of and response to significant and large-scale incidents, with audit missions in Ireland, Greece and Italy [18]. Member states remain primarily responsible for responding, and the EU's role starts when an attack causes major disruption, significant financial losses or substantial harm, or when an incident affects several countries and exceeds the capacity of one member state [19]. Every weakness in the findings is an arrangement, a funding control or a procurement delay. The report cites no individual incident [20].

The auditors also found that the European Commission's cyber situation centre, established in 2022 and largely supported by external providers, partly duplicates capabilities ENISA already has for monitoring threats and building situational awareness [14]. They called for better coordination to reduce that duplication [15].

What to watch

  • Publication of a formal arrangement between the CSIRTs network and EU-CyCLONe, and what it commits either side to on timing.
  • Closure of the ATHENA and ENSOC procurements, plus the cooperation agreements, classification system and technical standards the alert system lacked.
  • Whether the European Cybersecurity Competence Centre starts verifying beneficiaries' ownership and control assessments.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories